Skip to main content

Last Call Review of draft-ietf-uta-require-tls13-05
review-ietf-uta-require-tls13-05-dnsdir-lc-huston-2025-02-20-00

Request Review of draft-ietf-uta-require-tls13
Requested revision No specific revision (document currently at 12)
Type IETF Last Call Review
Team DNS Directorate (dnsdir)
Deadline 2025-03-04
Requested 2025-02-18
Authors Rich Salz , Nimrod Aviram
I-D last updated 2025-04-17 (Latest revision 2025-04-14)
Completed reviews Artart IETF Last Call review of -05 by Barry Leiba (diff)
Genart IETF Last Call review of -06 by Roni Even (diff)
Dnsdir IETF Last Call review of -05 by Geoff Huston (diff)
Secdir IETF Last Call review of -06 by Hilarie Orman (diff)
Tsvart IETF Last Call review of -06 by Martin Duke (diff)
Dnsdir IETF Last Call review of -06 by Geoff Huston (diff)
Opsdir Telechat review of -09 by Samier Barguil (diff)
Dnsdir Telechat review of -10 by Scott Rose (diff)
Dnsdir Telechat review of -12 by Geoff Huston
Assignment Reviewer Geoff Huston
State Completed
Request IETF Last Call review on draft-ietf-uta-require-tls13 by DNS Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/dnsdir/tX5Z6UQC6zLgdplTgvVlLSMSJVE
Reviewed revision 05 (document currently at 12)
Result Ready w/nits
Completed 2025-02-20
review-ietf-uta-require-tls13-05-dnsdir-lc-huston-2025-02-20-00
I was assigned as the dnsdir reviewer for draft-ietf-uta-require-tls13-05.
For more information about the DNS Directorate, please see
https://wiki.ietf.org/en/group/dnsdir

NIT: Should the enumeration of the known deficiencies of TLS 1.2 be contained
in the Introduction? The same considerations are described in Section 6, and
their summation in the Introduction seems to be superfluous.

NIT: the assertion in section 3 that "TLS applications will need to migrate to
post-quantum cryptography" is ddependent on the expectation of the lifetime of
the integrity of the encrypted object. The current advice on the immediate need
to use PQC is based on an integrity lifetime of 20 years.I would feel better if
the sentence read "many TLD applications..."

NIT: Section 4: "As a counter example, the Usage Profile for DNS over TLS
[DNSTLS] specifies TLS 1.2 as the default, while also allowing TLS 1.3." I fail
to appreciate the rationale for including this - the text is careful to note
that this applies to new protocols and DNS over TLS is not a new protocol at
this state.